Data Protection & GDPR Rights

Last updated: May 8, 2026

1. Introduction

This Data Protection Policy explains your rights regarding your personal data under the General Data Protection Regulation (GDPR) and other applicable data protection laws. It supplements our Privacy Policy and describes how we comply with data protection regulations.

2. Your Data Protection Rights

Under GDPR and other data protection laws, you have the following rights regarding your personal data:

2.1 Right of Access

You have the right to request access to your personal data that we hold. You can request a copy of your data in a portable, machine-readable format. We will provide this information within 30 days of your request.

How to Exercise: Click "Download My Data" in your account settings or email [email protected] with your request.

2.2 Right of Rectification

You have the right to correct inaccurate or incomplete personal data. You can update your profile information at any time through your account settings.

How to Exercise: Update your profile information directly in your account settings, or email [email protected] with the corrections you'd like us to make.

2.3 Right to Erasure ("Right to Be Forgotten")

You have the right to request deletion of your personal data, subject to certain exceptions. We will delete your data within 30 days of your request, unless we have a legal obligation to retain it.

Exceptions: We may retain your data if:

  • We need it to fulfill a contract with you
  • We have a legal obligation to retain it (e.g., tax records)
  • It's necessary for legal claims or defense
  • It's necessary for fraud prevention or security

How to Exercise: Click "Delete My Account" in your account settings or email [email protected] with your deletion request.

2.4 Right to Restrict Processing

You have the right to request that we limit how we use your personal data. We will restrict processing of your data while we verify your request or resolve a dispute about its accuracy.

How to Exercise: Email [email protected] with your request to restrict processing.

2.5 Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another organization. We will provide your data in JSON or CSV format within 30 days of your request.

How to Exercise: Click "Download My Data" in your account settings to receive your data in portable format.

2.6 Right to Object

You have the right to object to certain processing of your personal data, including:

  • Marketing communications (you can unsubscribe from emails)
  • Analytics and profiling (you can opt out of analytics cookies)
  • Processing based on legitimate interests

How to Exercise: Click "Unsubscribe" in any marketing email, or email [email protected] with your objection.

2.7 Right to Withdraw Consent

If we process your data based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing before withdrawal.

How to Exercise: Update your preferences in your account settings or email [email protected] to withdraw consent.

2.8 Right to Lodge a Complaint

You have the right to lodge a complaint with your local data protection authority if you believe we have violated your data protection rights. You can find your local authority at edpb.ec.europa.eu.

3. Legal Basis for Processing

We process your personal data based on one or more of the following legal bases:

3.1 Consent

We process your data with your explicit consent for purposes such as marketing communications and analytics. You can withdraw consent at any time.

3.2 Contract

We process your data to fulfill our contract with you, including booking dinners, processing payments, and providing customer support.

3.3 Legal Obligation

We process your data to comply with legal obligations, such as tax reporting, fraud prevention, and securities law compliance.

3.4 Legitimate Interest

We process your data based on our legitimate interests, such as:

  • Fraud prevention and security
  • Improving our services and user experience
  • Enforcing our terms and policies
  • Protecting our legal rights

4. Data Retention

We retain your personal data for as long as necessary to provide our services and fulfill the purposes outlined in our Privacy Policy. Specific retention periods are:

Data TypeRetention PeriodReason
Account InformationUntil account deleted or 3 years of inactivityService provision
Payment Data7 yearsTax and accounting requirements
Analytics Data26 monthsGoogle Analytics default retention
Email Logs90 daysTroubleshooting and support
Error Logs30 daysSystem monitoring and security
Backup Data30 days after deletionDisaster recovery

5. Data Processors and Third Parties

We share your personal data with the following third-party processors who assist us in providing our services:

ProcessorPurposeLocationDPA
StripePayment processingUSAYes
SendGridEmail deliveryUSAYes
Google AnalyticsAnalytics and usage trackingUSAYes
SlackNotifications and alertsUSAYes

All processors have signed Data Processing Agreements (DPAs) with us that ensure they comply with GDPR and other data protection regulations.

6. International Data Transfers

Your personal data may be transferred to, stored in, and processed in countries outside the European Union, including the United States. These countries may have data protection laws that differ from the EU.

Safeguards: We ensure adequate safeguards for international transfers through:

  • Standard Contractual Clauses (SCCs) with our processors
  • Data Processing Agreements (DPAs) with all third parties
  • Encryption and security measures
  • Limited data transfers (only necessary data)

7. Data Security

We implement industry-standard security measures to protect your personal data:

  • Encryption at rest (database encryption)
  • Encryption in transit (HTTPS/TLS)
  • Access controls and authentication
  • Regular security audits and penetration testing
  • Secure backup and disaster recovery
  • Employee training on data protection
  • Incident response procedures

8. Data Breach Notification

In the event of a data breach, we will notify affected individuals and relevant authorities as required by law, typically within 72 hours of discovering the breach.

Notification will include:

  • Description of the breach
  • Types of data affected
  • Likely consequences
  • Measures taken to address the breach
  • Contact information for further information

9. Children's Data Protection

Our services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that we have collected information from a child under 18, we will delete such information promptly.

10. Exercising Your Rights

To exercise any of your data protection rights, you can:

  • Use the features in your account settings (download data, delete account, update preferences)
  • Email us at [email protected]
  • Write to us at the address below

Response Time: We will respond to your request within 30 days. If your request is complex, we may extend this period by up to 60 days.

11. Data Protection Officer

We have appointed a Data Protection Officer (DPO) to oversee our data protection practices. You can contact our DPO at:

Data Protection Officer

Email: [email protected]

12. Contact Us

If you have questions about this Data Protection Policy or our data protection practices, please contact us at:

Investor Dinners

Email: [email protected]

Address: Austin, Texas

13. Updates to This Policy

We may update this Data Protection Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of our services after such modifications constitutes your acceptance of the updated policy.

Cookie Preferences

We use cookies to enhance your experience, analyze site traffic, and for marketing purposes. By clicking "Accept All," you consent to our use of cookies. You can customize your preferences or click "Reject All" to only use essential cookies.

Learn more about our cookie policy